SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-20043

For example, the contributor role does not have such rights, but this allowed them to bypass that.

MEDIUM 4.3EPSS 2.48%

Does this matter?

Lower severity and a low EPSS score (2.48%). Track it; it rarely justifies an emergency change on its own.

Description

In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS
2.48% probability · 84th percentile
CISA KEV
Not listed
Weakness
CWE-269
Affected
wordpress/wordpress · debian/debian linux
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.